ZeroHour

CVE-2026-69272

mass

Heap Buffer Overflow in Microsoft Standard XPS Enables Network Privilege Escalation

CVSS 3.1
7.1 high
EPSS
<1%p34
Published
()
Modified
AI analysis

CVE-2026-69272 is a heap-based buffer overflow (CWE-122) in Microsoft Standard XPS, the XPS document/print pipeline component bundled with Windows. An authorized, low-privileged attacker can reach the vulnerable code over a network path, but the CVSS vector (AV:N/AC:H/PR:L/UI:R) indicates exploitation requires high attack complexity and user interaction. Successful exploitation allows the attacker to elevate privileges on the affected system, with high impact to confidentiality, integrity, and availability. Potentially affected systems are any Windows installations containing the Standard XPS component; the provided data does not specify exact affected version ranges, which are published in Microsoft's advisory. There is currently no evidence of exploitation: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS is 0.4% over 30 days (34th percentile).

What to do: Apply the Microsoft security update addressing CVE-2026-69272 as published in the Microsoft Security Update Guide; the provided data does not include specific fixed version or KB numbers. Because exploitation requires an authenticated attacker plus user interaction and there is no known public exploit (EPSS 0.4%), treat this as standard-cycle patching rather than an emergency, and inventory client and server systems using XPS/print functionality to confirm coverage.

Affected
Microsoft Standard XPS (XPS print/document pipeline component in Windows)
Estimated exposure
massHundreds of millions of Windows devices (default Windows component; exploitation further limited by authentication and user-interaction requirements) — The Standard XPS component ships as part of Windows across client and server deployments, so plausible exposure tracks the very large Windows install base, though the provided data does not enumerate affected editions or versions and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges over a network.

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.